Skip to content
Menshen

Project · Microsoft 365 Security

From the report
to the fixes,
done.

An assessment tells you what is wrong and in what order to fix it. Remediation is the project that carries those fixes out in your tenant, by the same team that found them, in an agreed window and with a record of what changed.

One condition

Remediation always starts from an assessment

Without a picture of the tenant, fixing is guessing: you touch what is visible and leave untouched what genuinely exposes the organisation. If you do not have an assessment yet, that is where this starts. If you already have one, run by you or by another supplier, we go through it together and work from it.

The step before

Health & Security Assessment

Six pillars, international baselines, and a roadmap by time horizon. That roadmap is what this page carries out.

See the assessment

Scope

What gets fixed

The same pillars where the assessment finds the gaps. What enters the project is the findings in your report, not a fixed list.

  • Identity

    Turning MFA on, Conditional Access policies, separating privileged accounts, and reviewing the standing access nobody has looked at since it was granted.

  • Email

    Defender for Office 365 anti-phishing policies, fixing SPF, DKIM and DMARC, and closing the external forwarding rules created without oversight.

  • Devices

    Microsoft Intune security baselines and device compliance wired into Conditional Access, so the state of the machine starts to count.

  • Data

    Sensitivity labels, retention policies and external sharing limits across SharePoint and OneDrive.

  • Governance

    Administrative roles, just-in-time privilege through Privileged Identity Management, an active audit log, and a review of the consent granted to applications.

By horizon

Fixing everything at once breaks the operation

The order is not technical severity, it is impact on the people using the service. An access policy applied to the whole organisation with no warning is an incident in its own right.

Immediate

What exposes the organisation right now and can be fixed without disrupting how anyone works. It goes into the first window.

Short term

Fixes that change the experience of using the service, such as MFA or Conditional Access. They need communication and a pilot before the rollout.

Medium term

Work that depends on decisions your organisation has to make: data classification, retention, sharing rules. It runs once those decisions exist.

How it runs

Nothing changes without a window and a record

  1. 01

    Prioritisation

    We start from the assessment roadmap and agree with you what goes into each horizon. Not everything gets fixed at once, and it should not be.

  2. 02

    Window and rollback

    Every change has an agreed window and a rollback path defined before anything is touched.

  3. 03

    Execution

    The certified team applies the changes, recording the state before and after each one.

  4. 04

    Verification

    Another pass of the same engine that produced the assessment. The closing report compares the two points in time and names what is still outstanding.

The closing verification shows what moved and what is still outstanding. We do not promise a score: we promise you know exactly what state your tenant is in when the project ends.

Afterwards

Holding on to what you just fixed

A remediated tenant drifts again: new licences, new users, changes Microsoft makes on its own. Posture monitoring runs the same engine every month and tells you when something moves away from the line this project left it on.

When the pattern of findings shows the operation needs more than watching, the next step is managed services, in co-management or with Microsoft 365 run entirely by Menshen.

Next step

Talk about your remediation

If you already have an assessment report, bring it. We go through it with you and agree what goes into each horizon.